Skip to content

Single sign-on

Microsoft Entra ID

Connect Microsoft Entra ID (formerly Azure Active Directory) to SurrealDB to allow members of your organisation to sign in with their Microsoft accounts. You register an application in the Microsoft Entra admin center, then enter its details in a new connection in SurrealDB Studio.

Before you start, verify the email domain your company uses. You also need an Entra account that can register applications.

  1. In the Microsoft Entra admin center, open Entra ID, then App registrations.

  2. Select New registration.

The App registrations page in the Microsoft Entra admin center, with App registrations and New registration highlighted.

  1. Enter a Name, for example SurrealDB.

  2. Under Supported account types, select Single tenant only, so that only accounts in your directory can sign in.

  3. Under Redirect URI, select Web as the platform and enter https://auth.surrealdb.com/login/callback.

  4. Select Register.

The Register an application form in Entra, with the Web redirect URI and the Register button highlighted.

Entra opens the Overview of the new application. Copy the Application (client) ID.

The Overview page of the SurrealDB application in Entra, with the application (client) ID highlighted.

Open API permissions and make sure the application has the delegated Microsoft Graph permission User.Read. A new registration usually has it already. If it is missing, select Add a permission, then Microsoft Graph, then Delegated permissions, and add User.Read.

  1. Open Certificates & secrets.

  2. On the Client secrets tab, select New client secret.

  3. Enter a Description, for example SurrealDB, and choose when it Expires.

  4. Select Add.

The Certificates & secrets page in Entra, with the Add a client secret panel open and the steps numbered.

Copy the secret's Value, not its Secret ID. Entra shows the value only once, while you are still on the page.

Warning

Sign-in through this connection stops working on the date the client secret expires. Note the date, and create a new secret and update the connection in SurrealDB before then.

  1. Open Single sign-on in your enterprise and add a new connection.

  2. Select Microsoft Entra ID.

  3. Under Name the connection, enter a Display name. Members see this name on the sign-in screen.

  4. Under Enter the Microsoft Entra ID details, enter:

    • Directory domain: a domain of your directory, for example example.onmicrosoft.com.

    • Client ID: the application (client) ID from step 2.

    • Client secret: the secret value from step 4.

  5. Under Route sign-in domains, select the verified domains to send to this connection. This is optional, and you can change it later.

  6. Select Create connection.

The Set up Microsoft Entra ID section of the form shows the redirect URI, with a copy button beside it, if you need it again.

The New Microsoft Entra ID connection form in SurrealDB Studio, with the display name, directory domain, client ID, client secret and a routed domain filled in.

SurrealDB stores the client secret securely and does not show it again.

If you did not route a domain when you created the connection, route one now. Then choose the applications that people can sign in to with this connection.

Was this page helpful?